ITS Security Network Block - Malicious Activity
Incident Report for ITS Network & Systems
Resolved
Closing this announcement. Blocks will remain in place indefinitely. Please report if you have any academic or business communication that is dependent on these networks to the ITS Service Desk at (858)246-HELP(4357) or servicedesk@ucsd.edu.
Posted Mar 12, 2018 - 17:31 PDT
Monitoring
These network blocks will be left in place for the near future for security reasons. Please report if you have any academic or business communication that is dependent on these networks to the ITS Service Desk at (858)246-HELP(4357) or servicedesk@ucsd.edu.
Posted Mar 09, 2018 - 12:49 PST
Investigating
ITS Security is tracking high risk malicious activity from the following netblocks associated with a third party VPN service - ProtoVPN:

185.174.173.0/24
104.254.92.0/24
209.58.185.0/24

These networks have been temporarily border blocked to aid containment and response to these attacks. We understand there is likely some legitimate activity using this VPN service, and we apologize in advance for the inconvenience to those users. Users of the ProtoVPN service should connect directly to the campus network, and/or use the Campus VPN service. We will lift the block as soon as we have containment on this threat.
Posted Mar 08, 2018 - 15:16 PST